Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› When should organisations prioritise ISO 27001:2022 over finishing…
Governance, Ownership & Risk

When should organisations prioritise ISO 27001:2022 over finishing a certification effort on ISO 27001:2013?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 25, 2026 Domain: Governance, Ownership & Risk

Teams should prioritise ISO 27001:2022 when they are still early in implementation and have enough time to absorb the updated structure before their certification deadline. If certification is urgent or already well underway on 2013, finishing that path first can be more efficient, provided the organisation still plans a timely move before the 2025 transition cutoff.

Why the timing decision depends on implementation stage, not just the standard version

The practical question is not which version is “better” in the abstract, but which path reduces delivery risk without creating avoidable rework. If an organisation is still early, moving to ISO/IEC 27001:2022 Information Security Management can save effort by aligning the ISMS to the current structure once, rather than building controls against the older version and then remapping them later.

If certification is already close, the decision is more about execution efficiency than technical purity. Completing the 2013 effort can be sensible when the team has already invested in evidence, internal audit, and stage-readiness, provided the organisation does not lose sight of the transition deadline and the follow-on work is scheduled rather than deferred indefinitely.

What changes in 2022 that affects the certification path

iso 27001:2022 is not a different security philosophy, but it does reflect a cleaner control structure and updated control set. That matters because the standard now better aligns with current implementation patterns such as cloud security, access governance, and modern authentication expectations, which can reduce interpretation friction during design and audit.

For teams still designing policies, statements of applicability, or control ownership, the newer version avoids the common mistake of building around controls that are already being retired from practical use. For teams that have already stabilised a 2013-based programme, the gain from switching immediately is smaller, because most of the underlying management system work still transfers.

That is why the strongest decision signal is the amount of untouched implementation work remaining. If the organisation still needs to define controls, map evidence, and normalise ownership, the 2022 version is usually the more efficient destination. If the programme is mostly complete and the remaining work is certification administration, finishing the current path first may be the lower-friction choice.

How to choose the cheaper path without creating transition debt

The key trade-off is between near-term certification speed and medium-term rework. Choosing 2013 late in the cycle can be efficient, but only if the organisation treats the later transition as a real programme item with ownership, timeline, and budget. Otherwise, the company risks passing one audit and then rediscovering the same mapping and evidence work during transition.

When the 2022 path is preferred, the rationale is usually consolidation: one control model, one evidence structure, and one set of internal ownership decisions that can carry forward. That is especially useful where the organisation runs multiple environments, uses shared tooling, or has frequent control changes that would make a second mapping exercise expensive.

When the 2013 path is preferred, the rationale is usually schedule protection. If the organisation has already committed to audit dates, supplier dependencies, or regulatory deadlines, the immediate objective may be to complete the current certification and then manage the version change as a controlled follow-on project.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

ISO/IEC 27001:2022 provides the primary governance reference for this topic.

FrameworkControl / ReferenceRelevance
ISO/IEC 27001:2022A.5.15 — Access controlVersion choice affects how access controls are structured and evidenced in the ISMS.
A.5.23 — Information security for use of cloud services2022 updates reflect modern cloud control expectations that can influence implementation effort.
A.8.5 — Secure authenticationAuthentication control changes can affect remapping effort between 2013 and 2022.
Recommendation — Align the control set to the current standard so access control evidence maps cleanly during certification. Update cloud security control mapping before certification if cloud use is materially in scope. Revalidate authentication controls against the current annex before locking the certification path.

Practitioner Guidance

What to prioritise: Compare the remaining work, not the number of days left on the calendar. If the programme still needs major control design or policy rework, move to 2022; if it is already audit-ready, protect the current certification path and plan the transition immediately after.

What to verify: Confirm that the transition plan has an owner, a date, and a funded implementation window. A decision to finish 2013 is only low-risk when the organisation can show the 2022 move will happen on a defined schedule rather than as an open-ended intent.

Practitioner takeaway: The right choice is whichever path avoids duplicate work while still leaving enough time to complete the required transition cleanly before the cutoff.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 25, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org